IIS 4.0 and Site Server 3.0 Exposure via Improper Virtual Directory Naming
CVE-2000-0025

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
21 December 1999

Summary

IIS 4.0 and Site Server 3.0 are susceptible to a vulnerability that allows remote attackers to access the source code of ASP files unintentionally. This exposure occurs when an ASP file resides in a virtual directory with a name that contains certain extensions, such as .com, .exe, .sh, .cgi, or .dll. As a result, this misconfiguration can lead to unauthorized disclosure of sensitive information, enabling attackers to exploit the exposed source code.

References

EPSS Score

46% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.